Match plus provenance

KYC Data Provenance Review

A match is not proof of a person.

Provero helps KYC, IDV and fraud teams identify breached, recycled, synthetic and low-trust records before they become trusted evidence in downstream workflows. A database match proves records line up. It does not prove the record is fresh, consented, independent, or safe to trust.

To request a data provenance review, email support@provero.io

What Provero checks

Breach exposure across email, phone, IP, username, domain and password signals

Dead, unreachable or inconsistent phone numbers

IP fraud signals including proxies, VPNs, TOR, bots and abuse history

IP and location mismatches against the claimed identity

Impossible dates, invalid chronology and generated-looking fields

Source-level patterns across suppliers, campaigns and inbound data feeds

Why a match is not proof

A KYC match proves that two records line up. It does not prove that a real, consenting person is behind them. The same identity spine, name, address, postcode and date of birth, can carry completely different origin stories, and the match cannot tell you which one it is confirming.

The same stolen record arriving by many routes looks like corroboration, but it is redistribution. Once a record enters the data ecosystem it is sold, enriched and re-permissioned, so when it later appears in several places, that is often one origin arriving by several routes, not several independent witnesses.

Standard spine-only checks are blind to this by construction. Breach and fraud signals often live in the email, phone, IP, username and password data, which the spine does not include. A clean, compliant match can therefore confirm a breached or recycled record without ever surfacing a risk signal.

A match proves alignment. Provenance helps decide whether that alignment should be trusted.

Read the full argument: why a match is not proof of a person →

What a data provenance review reveals

A data provenance review reads the tells a spine-only check cannot see. These are examples, drawn from our own anonymised analysis, of the kinds of thing that are catchable, not a how-to.

Extreme breach concentration on a source

A single source running breach exposure above 90%, where a genuinely current, trusted feed sits around 40 to 50%.

Unusually old breach ages

Breaches averaging around nine years old, against around three years in clean data. Recent exposure is ordinary; very old exposure at scale is not.

Impossible chronology

People who appear not to have been born when their data was first breached, which cannot happen for a real human record.

Calendar dates that cannot exist

Date fields such as 30 February or 31 April. Nothing produces those except a generator inventing data.

Dead numbers that are breach-exposed

Phone numbers that are dead yet sit in a known breach, which is strange for supposedly fresh, recently collected traffic.

Inconsistent location signals

IP or location signals that do not line up with the claimed identity.

Synthetic-looking repetition or generated patterns

Fields that repeat or vary in machine-like ways, a sign of records assembled or generated rather than collected from real people.

Each tell is a pattern-level signal, not proof about any single person. A breach rate is a floor, not a ceiling, because it only counts breaches that have been reported and indexed, so the real figure is never lower than the one you see.

Two ways to use Provero

Option 1

Request a data provenance review

Send us a sample of inbound data, supplier data or existing records. We examine it for breach, chronology, phone, fraud, location and synthetic-pattern signals, then report what we found so you can decide what to trust, challenge, suppress or review.

To request a review, email support@provero.io

Option 2

Run the checks yourself

Use the APIs or bulk upload to run the same signals directly in your own workflow, on every record as it arrives or across an existing dataset.

See the checks you can run →

Run the provenance and fraud signals yourself

Each API returns an individual signal. The value comes from reading the pattern across them, manually, in a review, or in a single call with Multi-Validation. These run today as a real-time API or a bulk upload.

Where we are heading

We are building towards a single provenance-weighted outcome score that combines these signals automatically, so you read one number instead of assembling the pattern from individual checks yourself.

Today, you can run the individual checks directly or ask us to review the patterns for you. The score is not shipping yet; early accounts will get first access to it as it lands.

Early feedback

What early users say

"We tested Provero as an additional layer for our KYC data provenance due diligence and the outcome reports were very insightful. We could identify data that was part of a legacy breach, data that existed on national suppression files along with detailed phone and email validation flags. Really impressive solution and would recommend to anyone onboarding new data or to check existing datasets. It enabled us at Dataxcel to make informed decisions especially around compliance."
Lorcan Lynch, Dataxcel
Common Questions

KYC, IDV & Fraud FAQ

What is a KYC data provenance review?

A KYC data provenance review is an examination of identity records, or of a data source, for signals that a record may be breached, recycled, synthetic or otherwise low-trust before it becomes trusted evidence. Provero examines a sample of your inbound data, supplier data or existing records for breach, chronology, phone, fraud, location and synthetic-pattern tells, then reports what was found so you can decide which data and which suppliers to trust.

What does "a match is not proof of a person" mean?

A database match proves that two records line up. It does not prove that a real, consenting person is behind them, that the data is fresh, or that the sources are genuinely independent. The same identity spine can carry very different origin stories, and the same stolen record can appear through several routes and look like corroboration. A match proves alignment; provenance helps decide whether that alignment should be trusted.

What is match plus provenance?

It means an identity result should carry more than a yes or no match. Alongside the match it should surface the provenance signals: breach exposure, breach age, chronology, reachability, fraud and location signals, and source-level patterns, so a match can be read as strong evidence, weak corroboration, a risk signal, or not something to trust yet.

Does breach exposure mean a record is fraudulent?

No. Many legitimate people appear in old breaches because they have used the same email or phone for years. Breach exposure is a pattern-level signal, not proof about any single person. It becomes meaningful when breach rates and breach age are extreme, when chronology is impossible, or when it sits alongside other synthetic or recycled patterns. A breach rate is a floor, not a ceiling, because it only counts breaches that have been reported and indexed.

Can Provero replace my KYC or IDV provider?

No. Provero is not a KYC or IDV provider and does not make a final legal determination about a person. It surfaces provenance and fraud risk signals before and around your existing checks, so you can decide whether a record should be trusted, challenged, suppressed or reviewed, and reduce unnecessary downstream calls on records that were never worth them.

Where should identity data be checked?

At the point a record enters your system, where you still hold the full record: email, phone, IP and the surrounding metadata. Breach and fraud signals often live in fields a downstream spine-only match strips away. Once a record is through the door and redistributed across the chain, it is far harder to un-trust it.

How can I tell whether a supplier is feeding me breached, recycled or synthetic data?

Request a data provenance review. Provero examines a source across many records and reports which suppliers, campaigns or feeds consistently carry breach-heavy, old-breach, impossible-chronology or synthetic patterns, so you can see which source is feeding you low-trust data.

Can I run these checks by API instead of requesting a review?

Yes. Every signal is available as a direct API call or bulk upload: Breach Detection, HLR Phone Verification, Email Verification, IP Fraud Detection, IP Geolocation and Name Validation, or several together with Multi-Validation. Each returns an individual signal; the value comes from reading the pattern across them.

What signals does Provero use?

Breach exposure across email, phone, IP, username, domain and password signals; phone reachability; email deliverability and risk; IP fraud signals such as proxy, VPN, TOR, bot and abuse history; IP and location mismatch against the claimed identity; name plausibility; impossible dates and invalid chronology; and source-level patterns across suppliers and feeds. No single signal is a verdict; the pattern across them is what tells the story.

Is the provenance-weighted score available today?

No. The single provenance-weighted outcome score is on our roadmap, not shipping today. Today you can run the individual checks directly or ask us to review the patterns for you. Early accounts will get first access to the score as it lands.

Find out what your data, and your suppliers, are really feeding you

Request a data provenance review and we will examine your records or sources for breach, chronology, phone, location, fraud and synthetic-pattern tells. Prefer to run the signals yourself? Create a free account and call the checks directly.

To request a data provenance review, email support@provero.io